VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains a vulnerability due to incorrectly specified destination in a communication channel.
- "VoiceTra(Voice Translator)" for Android versions 9.1.3, 9.2.0
- "VoiceTra(Voice Translator)" for iOS versions 9.1.3, 9.2.0
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains the following vulnerability.
- Incorrectly specified destination in a communication channel (CWE-941)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 5.1
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Base Score 5.4
- CVE-2026-72506
Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
Update the Application
Apply the latest update according to the information provided by the developer.
| Vendor | Link |
|---|---|
| National Institute of Information and Communications Technology (NICT) | Multilingual Speech Translation App “VoiceTra”: Updated Version Released and Service Resumed |
RyotaK of GMO Flatt Security Inc. reported this vulnerability to NICT and coordinated. After the coordination was completed, RyotaK reported the case to JPCERT/CC to notify users of the solution through JVN.
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-72506 |
| JVN iPedia |
JVNDB-2026-000114 |